Live
Copilot Agent Blocking Broken: Admins Discover Policies Fail Across Teams, Outlook·MSFT +2.1%Visual Studio MCP GA Brings GitHub Server v0.12.1, but Prompt Injection Risks Demand Vigilance·NVDA +0.2%Microsoft Quietly Patches Copilot Flaw That Let Insiders Access Files Without Audit Traces·GOOGL +1.7%Tenable AI Exposure Debuts at Black Hat to Tackle Generative AI’s Hidden Attack Surface·AMZN +1.1%ChatGPT Gets Gmail and Calendar Access: OpenAI's Productivity Play Raises Security Flags·MSFT +2.1%Zenity Labs Unveils AgentFlayer: Zero-Click Exploits Hijack ChatGPT, Microsoft Copilot, and Salesforce Einstein·NVDA +0.2%Microsoft’s AI Coding Assistant Under Fire as GitHub Copilot Command Injection Chain Exposes Developers to Remote Code Execution·GOOGL +1.7%AgentFlayer Unleashed: Zero-Click Chains Turn Enterprise AI Agents into Stealth Insider Threats·AMZN +1.1%Copilot Agent Blocking Broken: Admins Discover Policies Fail Across Teams, Outlook·MSFT +2.1%Visual Studio MCP GA Brings GitHub Server v0.12.1, but Prompt Injection Risks Demand Vigilance·NVDA +0.2%Microsoft Quietly Patches Copilot Flaw That Let Insiders Access Files Without Audit Traces·GOOGL +1.7%Tenable AI Exposure Debuts at Black Hat to Tackle Generative AI’s Hidden Attack Surface·AMZN +1.1%ChatGPT Gets Gmail and Calendar Access: OpenAI's Productivity Play Raises Security Flags·MSFT +2.1%Zenity Labs Unveils AgentFlayer: Zero-Click Exploits Hijack ChatGPT, Microsoft Copilot, and Salesforce Einstein·NVDA +0.2%Microsoft’s AI Coding Assistant Under Fire as GitHub Copilot Command Injection Chain Exposes Developers to Remote Code Execution·GOOGL +1.7%AgentFlayer Unleashed: Zero-Click Chains Turn Enterprise AI Agents into Stealth Insider Threats·AMZN +1.1%

Prompt Injection

The latest Prompt Injection coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 7:37 AM
Latest Most Read Breaking
Sort
Admin Center · Agent Security

Copilot Agent Blocking Broken: Admins Discover Policies Fail Across Teams, Outlook

Organizations relying on Microsoft Copilot's agent policies to restrict AI access are confronting a stark reality: the controls have been breaking silently. In recent weeks, multiple independent...

Advertisement
Calendar · Chatgpt

ChatGPT Gets Gmail and Calendar Access: OpenAI's Productivity Play Raises Security Flags

OpenAI has quietly breached the walls of Google Workspace. Starting this week, ChatGPT Pro users can grant the AI direct access to their Gmail inboxes, Google Calendars, and Google Contacts—turning...

AI AI & Copilot Desk·48w ago
Agentflayer · Ai Security

Zenity Labs Unveils AgentFlayer: Zero-Click Exploits Hijack ChatGPT, Microsoft Copilot, and Salesforce Einstein

Zenity Labs has dropped a bombshell at Black Hat USA 2025: a new attack framework called AgentFlayer that lets adversaries silently hijack enterprise AI agents without so much as a mouse click....

AI AI & Copilot Desk·49w ago
Ai Security · Ci Cd Security

Microsoft’s AI Coding Assistant Under Fire as GitHub Copilot Command Injection Chain Exposes Developers to Remote Code Execution

A zero-click AI command injection flaw in Microsoft 365 Copilot, tracked as CVE-2025-32711 and nicknamed EchoLeak, laid bare a dangerous new attack surface in June 2025. The vulnerability carried a...

AI AI & Copilot Desk·49w ago
Access Control · Adversarial Testing

AgentFlayer Unleashed: Zero-Click Chains Turn Enterprise AI Agents into Stealth Insider Threats

At Black Hat USA 2025, Zenity Labs peeled back the curtain on a threat that security teams have long feared but rarely seen weaponized at scale: zero-click prompt injection attacks that silently...

AI AI & Copilot Desk·49w ago
272k Tokens · Azure Ai

GPT-5 Launch Sparks Musk-Nadella Clash, But Azure’s Model Router Quietly Redefines the Enterprise AI Battle

Elon Musk’s blunt warning that “OpenAI is going to eat Microsoft alive” after the August 7, 2025 launch of GPT‑5 crystallized a volatile moment in enterprise AI, but the far more telling...

AI AI & Copilot Desk·49w ago
Ai In Defense · Ai Security

Poisoned Calendars, Hijacked Chips, and Stealthy Phishing: Inside the Latest Cybersecurity Onslaught

A single poisoned Google Calendar invite can now raise your smart blinds and start a Zoom call without your consent. That unsettling reality emerged at this year’s Black Hat conference, where...

AI AI & Copilot Desk·49w ago
Ad Fraud · Ai Security

Google Gemini Exploit Can Control Smart Homes, as Nvidia Rejects Government Backdoor Demands

A simple "thank you" is all it takes for attackers to hijack Google's Gemini AI and control your smart home, researchers revealed at Black Hat this week. The demonstration, which showed how a...

AI AI & Copilot Desk·49w ago
Ai · Ai Risks

Black Hat 2025: Zero-Click Exploits Can Hijack ChatGPT, Copilot, and Einstein Without a Trace

Security researchers at Zenity Labs have dropped a bombshell at Black Hat USA 2025: a new breed of zero-click exploit chains can silently hijack enterprise AI agents, including OpenAI’s ChatGPT,...

AI AI & Copilot Desk·49w ago